CVE-2026-103222
Received Received - Intake

Integer Overflow in Blosc C-Blosc2

Vulnerability report for CVE-2026-103222, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: VulDB

Description

A vulnerability was determined in Blosc C-Blosc2 up to 3.3.2. This impacts the function blosclz_decompress of the file blosc/blosclz.c of the component blosclz Decompression. Executing a manipulation can lead to integer overflow. The attack may be launched remotely. A high complexity level is associated with this attack. The exploitability is said to be difficult. Upgrading to version 3.3.3 will fix this issue. This patch is called fe2964d114d97847f56570a0ab2be2c57ccbeedc. The affected component should be upgraded.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
blosc c-blosc2 to 3.3.2 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-190 The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.
CWE-189

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an integer and pointer overflow issue in the Blosc C-Blosc2 library up to version 3.3.2. It occurs in the blosclz_decompress function where a loop accumulates match lengths without bounds, allowing crafted input to inflate length values to 255 MB or more. This can cause heap out-of-bounds writes on 32-bit platforms and signed 32-bit integer overflow on 64-bit systems.

Detection Guidance

To detect this vulnerability, check the version of Blosc C-Blosc2 installed on your system. Run: blosc2 --version or check the library version in your package manager. If the version is below 3.3.3, the system is vulnerable.

Impact Analysis

An attacker could exploit this to execute arbitrary code or cause denial-of-service by triggering heap corruption or integer overflows. The attack requires remote access and has high complexity but could lead to data breaches or system crashes if successful.

Compliance Impact

The vulnerability could lead to unauthorized data access or corruption due to heap out-of-bounds writes or integer overflows, which may violate data integrity and confidentiality requirements in GDPR and HIPAA. Unpatched systems risk non-compliance with these regulations.

Mitigation Strategies

Upgrade Blosc C-Blosc2 to version 3.3.3 or later. Use your package manager to update: e.g., apt-get upgrade c-blosc2 or pip install --upgrade c-blosc2. Verify the update with blosc2 --version.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103222. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart